- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
09-05-2019 09:40 PM - edited 09-05-2019 10:31 PM
I am setting up backup user-id agent 8.1.10-2 on Windows 2016 Standard server.
I have given all the required access to the user-id agent admin account but its not working / refusing to start.
I am using the same credential on existing UID agent 7.0.8-13 running on Windows 2008 R2 and it runs fine.
I attaching error messgae when starting UID service and corresponding log generated in UID logs.
UID Log
09/05/19 09:42:52:190[ Info 2357]: ------------Service is being started------------
09/05/19 09:42:52:190[ Info 2364]: Os version is 6.2.0.
09/05/19 09:42:52:190[Error 675]: Cannot open config reg log key with error 5(Access is denied.
)!
09/05/19 09:42:52:190[Error 2382]: Start error -1!!
09/05/19 09:42:52:190[Error 764]: Device listening thread stops timeout
03-15-2023 07:50 PM
Please note that Palo Alto has a mistake in the latest versions of the documentation.
Step 1, Section 4, Bullet 1 -
This cost me about 4 hours this evening trying to figure out why I was getting the same "Cannot open config reg log key with error 5(Access is denied." error. Hopefully it saves someone else some time in the future. The other article referenced above does say it could be "EITHER" of these two locations. However, for me that was incorrect. I stopped looking when I found the first location, but both registry locations actually existed. The first one is related to Global Protect and appears to have no effect on the User ID Agent service. I am running it by only setting permissions on the second location I provided.
11-27-2019 10:57 PM
I have exactly the same issue on a Windows Server 2019 member server. How was this issue resolved? @Nischal
02-04-2020 08:22 AM
https://supportcases.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClEuCAK
Please follow the instructions in the URL provided. It did resolve my issue.
02-06-2020 05:54 AM
hey, please check if user-id is having administrator level access on the server. I have faced same issue and it was resolved by giving required access level to user-id on the server.
04-26-2021 07:38 AM
Do you mind sharing the details of your case file here?
06-09-2021 07:40 AM
This is the best answer I've seen to this problem
https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA10g000000ClEuCAK
08-23-2021 03:16 PM
The resolution in my case was to provision local admin rights to the service account. I hope this helps.
03-19-2022 08:42 PM
Hello Guys,
Facing same issue on my user-Id agent software. Unable to start the service. All the admin access are provided.
Any resolution ?
03-15-2023 07:50 PM
Please note that Palo Alto has a mistake in the latest versions of the documentation.
Step 1, Section 4, Bullet 1 -
This cost me about 4 hours this evening trying to figure out why I was getting the same "Cannot open config reg log key with error 5(Access is denied." error. Hopefully it saves someone else some time in the future. The other article referenced above does say it could be "EITHER" of these two locations. However, for me that was incorrect. I stopped looking when I found the first location, but both registry locations actually existed. The first one is related to Global Protect and appears to have no effect on the User ID Agent service. I am running it by only setting permissions on the second location I provided.
09-25-2023 08:46 AM - edited 09-25-2023 08:52 AM
This is the fix! Thank you Stephan!
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!